Threat Advisory

Apple Private Cloud Compute Vulnerability Facilitates Privileged System-File Changes

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-20685, with a CVSS score of 6.5, is a path traversal vulnerability affecting Apple’s Private Cloud Compute (PCC), potentially allowing attackers to write files as root during node boot and redirect sensitive AI inference telemetry to an external server. The flaw exists in darwin-init, the first userspace process launched on a PCC node, which downloads, extracts, personalizes, and installs cryptex packages before triggering a userspace reboot into the normal operating environment. A malicious tar archive that did not match known Apple archive signatures could be passed to a generic extraction function that appended archive entry names to the intended output path without properly validating path traversal sequences such as ../../../../. This could allow a crafted archive to escape its extraction directory and write attacker-controlled files to persistent locations on the PCC node’s writable data volume, including sensitive data that could remain available after the userspace reboot. The vulnerability could also expose sensitive information by redirecting PCC telemetry to an attacker-controlled endpoint, potentially revealing details about how a PCC node processes AI requests. The vulnerability presents significant security and business risks by potentially compromising the confidentiality and integrity of sensitive data processed by PCC nodes.

RECOMMENDATION:

We recommend you to update Apple Private Cloud Compute to version 5E290.3 or later.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-20685, with a CVSS score of 6.5, is a path traversal vulnerability affecting Apple’s Private Cloud Compute (PCC), potentially allowing attackers to write files as root during node boot and redirect sensitive AI inference telemetry to an external server. The flaw exists in darwin-init, the first userspace process launched on a PCC node, which downloads, extracts, personalizes, and installs cryptex packages before triggering a userspace reboot into the normal operating environment. A malicious tar archive that did not match known Apple archive signatures could be passed to a generic extraction function that appended archive entry names to the intended output path without properly validating path traversal sequences such as ../../../../. This could allow a crafted archive to escape its extraction directory and write attacker-controlled files to persistent locations on the PCC node’s writable data volume, including sensitive data that could remain available after the userspace reboot. The vulnerability could also expose sensitive information by redirecting PCC telemetry to an attacker-controlled endpoint, potentially revealing details about how a PCC node processes AI requests. The vulnerability presents significant security and business risks by potentially compromising the confidentiality and integrity of sensitive data processed by PCC nodes.

RECOMMENDATION:

We recommend you to update Apple Private Cloud Compute to version 5E290.3 or later.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu